URLhaus Database

You are currently viewing the URLhaus database entry for https://niku-q.co.jp/ms/43zbd-t76-362/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:428848
URL: https://niku-q.co.jp/ms/43zbd-t76-362/
URL Status:Offline
Host: niku-q.co.jp
Date added:2020-08-10 20:09:12 UTC
Last online:2020-08-13 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-10 20:10:02 UTC to abuse{at}sakura[dot]ad[dot]jp)
Takedown time:2 days, 6 hours, 5 minutes Poor (down since 2020-08-13 02:15:14 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-12invoice-J883-08239567.docdoc f4ba3a56f466f00fd12e433b57baf505f8f237c83a901d453317cb724a7538b1Virustotal results 59.32% Heodo
2020-08-11invoice_FB06_473310613.docdoc 4809328436efcae1791fa4770d4f7158cc69e9dcf26dcce66189e3ce63af2a44Virustotal results 43.33% Heodo
2020-08-11Invoice-MEZK29-863483.docdoc ad8067bbc1e7e3ed6a24c8387fd0cfcc072810a1fe43e6cae9a1a46682f1dfeaVirustotal results 43.33% Heodo
2020-08-11Invoice-YEGE1285-336230776.docdoc df9751edb6d3f6da4e475cc3b05844cb0833623d6e9f3d268a38611dd8bd15a3Virustotal results 42.11% Heodo
2020-08-11Invoice-KRLL737-4866806.docdoc c1fc85d3b078b060a5335fd6ccf06322f2e7f97c39ff74defd85719891c024d2n/a Heodo
2020-08-10invoice-GCFA37-26283848.docdoc 2ed80e234eddcbf09463cc2ef0009ebe173d3a21995aa99dbdbc3764bf9171f4Virustotal results 40.98% Heodo
2020-08-10INVOICE_V98_387489893.docdoc 98da13994d0e4eaf92b83f53e2532f3b91437949fe1318902a029096c742d57dVirustotal results 41.67% Heodo
2020-08-10Invoice_XVFJ6833_169401814.docdoc 6a9bb8fc612b44e9be188fe10a33599eef5883cd35049d99d1b31ea6c0237c7bVirustotal results 41.67% Heodo
2020-08-10INVOICE_48_77970365.docdoc b579309f5fc1facdee46bda7e5f729e9951897bdbbeb2c4804d66b67ce0fe64aVirustotal results 40.68% Heodo
2020-08-10Inv YAW125 912032810.docdoc 577541e163fd3e3cc0366f5080580723d039ed20d4f7976bbd7b2f73a92fb957Virustotal results 42.37% Heodo
2020-08-10INVOICE_PWRE999_590684997.docdoc 2eebde5c616671da6343d79250d741278cdfc7b19af5ee5a43fdbb115b906077Virustotal results 40.68% Heodo
2020-08-10Invoice_BGH08_975526.docdoc 705e718dccff08f8277bc1b0272bb945ed6346a0bfc50f80558691982c8e9c39Virustotal results 40.00% Heodo
2020-08-10Invoice_028_4855247.docdoc 29295815cb9d8286a2a49e7a93c614afbccd8f45598396767c169d447cfd6a92Virustotal results 40.68% Heodo
2020-08-10Invoice-B6-800884.docdoc c0e4049bf80d298117b7f7844916057a97ac0cabf36e481f6117e7d8d6a40eadVirustotal results 40.98% Heodo
2020-08-10invoice-YFNJ7-1269901.docdoc 14045c2a1f8106f62cca9878b82b62d33cbe757e36d4f41266e905a0d3db4121n/a Heodo
2020-08-10InvN39302288416.docdoc 1121514cc677af08164377f783c7cdb3a7929bf28b4652291c02d6fa0b34b57cVirustotal results 40.98% Heodo
2020-08-10invoice-T320-892632.docdoc 88b266b5360ce44a792d3048d108d64b2e6e95a016f3adf662f4d2a4a9541b1eVirustotal results 40.32% Heodo
2020-08-10Inv-C6-409956.docdoc 08f5371494208247e62ba827c04be32d8e6ddd081e2d6bde0fe4f6d0d463a5baVirustotal results 41.67% Heodo